Five Charged in “Russian Coms” Fraud Platform Case

2026-07-14T08:52:15Z16a23135f24bcd0bb945dd89365118b6e59dc8907a5445ee45e6af0f425d1073
AWS-GovCloudColdFusionEvilginxGigaWiperGodDamnJadePufferMFA-bypassNetNutOAuthPoisonXRyukSNMPShareFileagentic-AIcloud-securitycredential-theftespionagemalwarephishingransomwareroutersstate-sponsoredsupply-chain-securityvulnerabilitieszero-day

What happened

A cluster of high-impact cyber incidents and vulnerabilities was reported: active exploitation of a maximum-severity Adobe ColdFusion flaw (CVSS 10.0), an open directory exposing three Evilginx phishing operators enabling MFA bypass, and a novel OAuth Client ID spoofing technique targeting Microsoft Entra ID that creates stealthy cloud access paths. State-linked activity and targeted espionage were highlighted (Russian actors scanning routers via weak SNMP credentials; Chinese and Indian espionage against a Pakistani police force), while ransomware/malware developments included new destructive

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
16a23135f24bcd0bb945dd89365118b6e59dc8907a5445ee45e6af0f425d1073
Enrichment time
2026-07-14T08:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Five Charged in “Russian Coms” Fraud Platform Case · Baitaphish